Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing unauthenticated remote attackers to execute arbitrary code and cause denial-of-serv...
F5 disclosed a critical vulnerability in NGINX, identified as CVE-2026-42533, which can lead to remote code execution (RCE) and denial-of-service (DoS) attacks. The flaw is a heap buffer overflow triggered by crafted HTTP requests that exploit unsafe regex processing in the map directive. This vulne...
On June 17, 2026, multiple critical vulnerabilities (CVE-2026-42055, CVE-2026-42530, CVE-2026-48142) affecting Fedora's Nginx modules were disclosed. These vulnerabilities allow for potential remote code execution and denial-of-service attacks. The affected modules include nginx-mod-fancyindex, ngin...
A critical unpatched vulnerability, XRING, has been identified in the XQUIC library, affecting HTTP/3 servers. This flaw allows any remote, unauthenticated client to crash servers using XQUIC with as little as 260 bytes of legal QPACK traffic. All releases of XQUIC up to v1.9.4 are impacted, includi...